InstantAccess Malware hitting my net. Classified as a Trojan but having trouble determining how the queries are being started. Possible malicious redirect from another website. Reference is based off a hash, but I do not see that hash on my net. A few IP Addresses, mostly hosted by confluence-networks.com. I searched the IPs for associated domains and it all seems to be garbage spam/parked domains. The signatures to look for in the URL would include: /sk-logabpstatus.php?a= /sk-logabpstatus.php?b= List of domains are posted on the pastebin reference, and images are posted on my twitter. I searched these IPs on my net and the logs all show junk traffic. VirusTotal reference is for a new file only 4-5 days ago.
Created: 2026-02-23
Indicatorsは見つかっていない。
このPulseに見つかったCVEはありません。